Skip to main content
btan
Staff & Editor
Staff & Editor
February 17, 2025

Troubleshooting Tip: FortiClient SAML User Verification with Entra ID is failed with 'expecting attribute "userPrincipalName"' message

  • February 17, 2025
  • 0 replies
  • 1772 views
Description This article describes how to resolve the 'expecting attribute "userPrincipalName"' message when performing FortiClient SAML User Verification with Entra ID.
Scope FortiClient EMS v7.0, v7.2 and v7.4
Solution

After configuring SAML user verification with Entra ID, the endpoint is getting 'The SAML configuration you are using to authenticate is expecting the userPrincipalName attribute "userPrincipalName" error message:

 

feb-kb3-1.PNG

 

This is due to there being non-default Entra ID settings in the Azure tenant. 

 

To resolve this:

  1. In the Entra ID application, go to Single sign-on.
  2. Under Attributes & Claims, add a claim for userPrincipalName:


feb-kb3-2.PNG

Select Add a new claim:

  • In the Name field, type userPrincipalName.
  • In the Source attribute field, select user.userPrincipalName.

 

  1. Save the configuration. On the endpoint FortiClient, enter the Invitation Code with SAML verification, the verification will be successful.

 

feb-kb3-3.PNG